Categories
Compliance Into the Weeds

Compliance into the Weeds: Scoular Company FCPA Settlement: Cartel Links, Border Trade Risks, and Compliance Lessons

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent FCPA resolution with the Scoular Company. Both Tom and Matt have blogged on this matter, so check out the Resources link below for additional discussions.

The recent FCPA enforcement action against Scoular Company involved a $10.2 million payment and a three-year deferred prosecution agreement over bribes by third-party customs brokers to Mexican border officials to expedite cross-border shipments. DOJ emphasized alleged cartel connections, including a strong statement from the U.S. Attorney for the Western District of Texas, which raised questions about expanded local U.S. attorney involvement and how cartel or potential FTO designations could heighten trade and compliance risks. The company received no voluntary self-disclosure credit but got a 25% discount, with remediation cited (including dropping brokers and strengthening tone at the top). They highlight off-channel WhatsApp use, the lack of released key documents (DPA, statement of facts, criminal information), and practical compliance takeaways on third-party oversight, data analytics, and risk assessments.

Resources:

Matt in Radical Compliance

Tom in FCPA Compliance and Ethics Blog

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.

Categories
Blog

Connected Compliance: Part 3 – Why Every Investigation Is a Culture Opportunity for Your Organization

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. In Blog 1, we examined communication as a compliance control. In Blog Post 2, we showed how those communications and other operational signals create a dynamic risk radar. Today in Blog Post 3, we ask what happens when a signal becomes an allegation as an introduction to how and why every investigation can be an opportunity to both pressure-test and build out your culture.

A hotline report, audit exception, control override, manager escalation, or unusual transaction may begin as just another compliance signal; once the company decides it requires investigation, the stakes change. The organization must establish what happened, protect people and evidence, make defensible decisions, and strengthen the program.

That makes an investigation more than a fact-finding exercise. It is a visible test of governance. Employees watch who is interviewed, how leaders behave, whether the process appears fair, whether high performers receive special treatment, and whether the company acts when misconduct is substantiated. Details should remain confidential, but the organization cannot erase the cultural impact. Every investigation sends a message.

Credibility Is Built Before the First Interview

The strongest investigations begin with disciplined triage. Before scheduling interviews or collecting data, the company should first identify the immediate risks that require action. Is anyone’s health or safety at risk? Could misconduct be continuing? Is evidence vulnerable? Does the allegation implicate financial reporting, government contracting, sanctions, corruption, product integrity, cybersecurity, privacy, or another obligation requiring prompt escalation?

Containment is not a conclusion. Suspending access, preserving records, pausing a payment, separating employees, or protecting a reporter may be necessary while the facts remain unresolved. The decision should be proportionate, documented, and revisited as evidence develops.

Triage should identify the functions that need to participate without turning the matter into a committee project. One person should own the process, one decision-maker should approve material scope changes, and communication lines should be defined at the outset.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places investigations squarely inside its test of program effectiveness. The 2024 Evaluation of Corporate Compliance Programs (ECCP) asks, “How does the company ensure that investigations are properly scoped?” It then asks what steps the company takes to ensure investigations are “independent, objective, appropriately conducted, and properly documented,” as well as how the company determines who should conduct an investigation.

Those words provide a practical quality standard. Proper scope means the investigation addresses the allegation and reasonably connected issues without drifting into an unlimited inquiry. Independence means the investigator is free from conflicts and improper business pressure. Objectivity requires a search for facts that may confirm or disprove the allegation. Appropriate conduct includes lawful evidence collection, fair treatment of witnesses, and proportionate methods. Proper documentation allows the company to explain what it did, why it did it, and how it reached its conclusions.

DOJ also asks whether the company applies timing metrics, monitors outcomes, and ensures accountability for findings and recommendations. Later, the ECCP describes a working program as having an “appropriately funded mechanism for the timely and thorough investigations” of allegations or suspicions of misconduct. The point is not speed at any cost. It is disciplined responsiveness supported by adequate resources.

Scope the Question, Not the Desired Answer

A written investigation plan should define the allegation, relevant policy or legal issues, time period, business units, people, data sources, immediate risks, and proposed work. It should identify the standard used to reach findings and the expected form of the report. It should also record what remains outside scope.

The plan must be flexible. Evidence may reveal additional conduct, another geography, a control failure, or management involvement. The investigator should document the new information, assess its materiality, identify any additional resources or conflicts, and obtain appropriate approval for expansion.

This discipline prevents a scope narrowed to contain the issue and investigation drift that delays a conclusion. A credible process follows the evidence while preserving a clear line of sight to the original allegation.

Choose the Investigator for the Risk

Not every matter requires outside counsel, and not every matter should remain inside the company. The choice should turn on credibility and capability, not habit. Internal investigators may understand the business and manage routine matters efficiently. External counsel or specialists may be appropriate when allegations involve senior leadership, significant legal exposure, government reporting, material financial impact, technical evidence, cross-border restrictions, litigation, or concerns about internal independence.

The company should establish decision criteria before a crisis. Who determines whether compliance, legal, human resources, internal audit, security, or outside counsel will lead? What conflicts require recusal? When does the audit committee or another independent authority oversee the matter? Which technical experts may be needed, and how will their work be directed? An outside law firm’s letterhead does not create independence. It comes from clear authority, freedom from interference, sufficient resources, access to evidence, and an escalation route when investigators encounter resistance.

Protect the Privilege with Precision

The attorney-client privilege can protect confidential communications seeking or providing legal advice, but an investigation is not privileged simply because a lawyer attends. Privilege rules are jurisdiction-specific, and careless circulation, unclear roles, or unnecessary third-party involvement can create risk.

At the beginning, counsel should define the legal purpose, identify the client and team, establish communication and documentation protocols, and explain confidentiality expectations. Team members should know which communications seek legal advice, where documents will be stored, and who may receive them. Over-labeling every document as privileged does not create stronger protection. It can undermine discipline and complicate later disclosure decisions. The better approach is to use privilege deliberately, involve counsel where legal advice is genuinely required, and preserve a reliable factual record that supports the company’s decisions.

Treat Witnesses as People, Not Evidence Containers

Witness interviews often determine whether employees experience the investigation as fair. The investigator should explain the purpose of the interview, the investigator’s role, expectations for truthful cooperation, applicable confidentiality limits, and the company’s prohibition against retaliation. The interviewer should not promise complete secrecy, prejudge the allegation, coach testimony, or imply that raising concerns created the problem.

Respect improves evidence quality. Employees are more likely to provide complete information when questions are neutral, and the interviewer listens before challenging inconsistencies. Cultural, language, disability, and power dynamics may affect participation and should be addressed thoughtfully.

Anti-retaliation protection requires more than an opening statement. Compliance and human resources should identify foreseeable risks of retaliation, monitor employment actions and workplace behavior, provide a safe escalation channel, and respond quickly to concerns. Retaliation may be subtle: exclusion, schedule changes, lost opportunities, hostile supervision, or reputational harm. A technically sound investigation can still damage culture if the reporter or witnesses pay a price for participating.

Preserve Evidence and Measure the Right Clock

Evidence management must begin early. Relevant emails, collaboration messages, mobile communications, transaction records, system logs, personnel documents, and physical evidence all require preservation. Collection should follow applicable law, privacy requirements, company policy, and forensic protocols. The team should document sources, custodians, dates, gaps, and chain of custody where necessary. Always remember the first question the DOJ will ask after you self-disclose is, “Do you have the documents tied down?

Timeliness should be measured, but the metric must support quality. Useful measures include time from intake to triage, time to investigator assignment, aging by risk category, days awaiting business action, time from finding to remediation, and overdue reporter updates. A single average completion target can create pressure to close simple matters quickly or rush complex ones. Status reviews should ask what is delaying the matter, whether scope remains appropriate, whether interim protections still work, and whether new risks require escalation. The objective is a process that explains delay, removes bottlenecks, and prioritizes higher-consequence matters.

Move Beyond the Bad Actor

An investigation that identifies who violated a policy but not why the system allowed it has completed only half the work. DOJ asks whether investigations identify “root causes, system vulnerabilities, and accountability lapses,” including those involving supervisors and senior executives.

Root-cause analysis should examine incentives, performance pressure, control design, access rights, training, supervision, third-party oversight, data availability, prior warnings, and the consistency of discipline. Did the policy prohibit the conduct but the workflow reward it? Did a manager ignore a red flag? Did an exception process become the normal process? Did earlier reports reveal the same weakness?

The answer should drive remediation, including discipline, control redesign, policy revision, monitoring, training, leadership changes, third-party action, disclosure, or resource reallocation. Each action needs an owner, deadline, evidence, and testing. Otherwise, the investigation becomes a historical record rather than a compliance control.

Close the Case and the Cultural Loop

A reasoned closure record should state the allegation, scope, steps taken, evidence considered, credibility analysis, findings, and approved response. Discipline should be consistent across ranks and levels of commercial importance, with deviations documented. Investigation data should then feed the risk assessment, training plan, control testing, and management reporting.

The reporting party also matters. Without disclosing confidential personnel information, the company can acknowledge that the review is complete, thank the person for speaking up, restate anti-retaliation protections, and provide a contact for further concerns. Silence after intake encourages employees to conclude that nothing happened.

This is the connection across the series. Communication brings information into the program. Dynamic risk assessment helps the company recognize its significance. Investigation converts allegations into facts, accountability, and learning. Therefore, join us for Part 4 tomorrow, as we will demonstrate the front door to that process: how an effective whistleblower program gives employees safe, accessible ways to report and confidence that speaking up will lead to credible follow-through.

Bonus Questions for Compliance Professionals

  1. Who has authority to triage an allegation and order immediate containment or preservation measures?
  2. What written criteria determine who should lead an investigation and when independent oversight or outside counsel is required?
  3. Can the company show that recent investigations were properly scoped, independent, objective, timely, and documented?
  4. Which stages of the investigation create the greatest delays, and are those delays risk-based or simply unmanaged?
  5. How does the organization monitor subtle retaliation against reporters and witnesses?
  6. Do investigation reports identify control failures, incentives, supervisory accountability, and root causes in addition to individual misconduct?
  7. What evidence shows that completed investigations changed controls, training, discipline, resources, or risk assessment?
  8. How does the company communicate appropriate closure to reporters without compromising confidentiality?
Categories
Blog

Connected Compliance: Part 2 – From Risk Register to Risk Radar

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. Blog 1 examined communication as the control that connects those elements. In this Part 2, we examine what compliance must do with the intelligence that communication produces.

The traditional risk assessment was built for a world that moved more slowly. Compliance gathered a group of leaders, reviewed enforcement trends, scored familiar risks, produced a heat map, and returned to the exercise the following year. That process still has value, but it is no longer enough.

Today, a new market restriction, customer demand, artificial intelligence deployment, supply-chain disruption, sanctions measure, or data rule can alter the company’s risk profile before the annual plan is approved. The central question is therefore not whether the organization has a risk register. It is whether compliance has a risk radar that can detect change, decide what matters, assign ownership, and translate the signal into action.

Every Compliance Risk Has a Political Dimension

Compliance obligations do not develop in a vacuum. They reflect choices made by governments about national security, trade, technology, labor, privacy, corruption, competition, and corporate accountability. For a multinational company, those choices may conflict, overlap, or change with little notice. Particularly in this political age, the single most-used byword is volatility.

That makes geopolitical awareness a compliance capability. It does not require the CCO to become a foreign-policy analyst. It requires the compliance function to understand how political priorities can become legal obligations, enforcement pressure, customer expectations, or operational constraints. Export controls can reshape product access. Sanctions can alter payment and counterparty risk. Forced-labor requirements can reach deep into a supply chain. AI rules can change how a business collects data, develops products, and makes decisions.

The practical lesson is that legal change is often the last stage in a longer policy development process. Compliance should monitor the earlier signals: legislative proposals, agency speeches, enforcement patterns, trade measures, customer questions, supplier difficulties, and operational workarounds. These indicators do not all demand a program change, but they should enter a disciplined triage process.

What the DOJ Is Really Asking

The Department of Justice has made dynamic risk assessment part of the effectiveness inquiry. The 2024 Evaluation of Corporate Compliance Programs (ECCP) directs prosecutors to consider “emerging risks as internal and external circumstances impacting the company’s risk profile evolve.” This risk profile can change due to factors outside a company’s control or its own business decisions. Moreover, the ECCP language moves risk assessment beyond a scheduled document and into continuous management.

DOJ then asks: “Is the company’s approach to risk management proactive or reactive?” The distinction is critical. A reactive program updates controls after a failure, enforcement action, or audit finding. A proactive program uses operational information across functions to identify change before misconduct occurs. The ECCP also asks whether periodic review is merely a point-in-time exercise or draws on continuing access to operational data, and whether the results lead to updates in policies, procedures, and controls.

The enforcement question is not whether the company predicted every development. No program can. The question is whether the company had a reasonable process for identifying material changes, directing resources to higher-risk areas, documenting its decisions, and revising the program over time.

Build the Risk Radar From Multiple Signals

A dynamic risk process begins with a wider field of vision. Regulatory alerts and outside counsel updates are useful, but they show only part of the environment. Some of the earliest warnings come from inside the business. Sales may see unusual customer demands in a new market. Procurement may find suppliers unable to provide origin information. Finance may identify payment routes that no longer fit the expected transaction. Information security may discover employees using unapproved AI tools. Human resources may raise concerns about retaliation or pressure related to performance targets. Audit may identify recurring exceptions. Hotline reports and investigations may reveal a pattern that a heat map missed.

Compliance should bring these signals together through a repeatable cadence. A quarterly cross-functional review can examine changes in the business model, geography, products, third parties, technology, enforcement, and employee concerns. High-velocity risks may require monthly or event-driven review. The objective is not to create another committee. It is to establish a reliable place where weak signals are compared, challenged, and assigned.

Or simply look at the changes wrought by the Trump Administration in 2026 alone. Venezuela is now open for business. How about the Democratic Republic of Congo? See here and here. Of course there is Iran, but you have to ask what week it is and are we doing business with Iran or are we at war with Iran.

Give One Person the Clock

Emerging risks often fall between organizational boxes. Legal understands the rule. Compliance sees the control issue. Operations owns the process. Procurement controls the supplier relationship. Technology owns the system. To use a well-worn maxim, if everyone is in charge, no one is in charge. In the corporate world, when everyone is generally responsible, no one is specifically accountable. This is both why and where compliance needs to step up its game.

Every material risk needs a named owner with the authority to convene the necessary functions, set deadlines, escalate disagreements, and report on the disposition. That person does not perform every task. The owner keeps the clock, maintains the decision record, and ensures that the issue does not disappear between meetings.

Governance should also define escalation triggers. A credible framework identifies which developments require immediate executive attention, which can be handled through a working group, and which should remain under observation. Without thresholds, organizations either under-escalate material risk or flood leadership with undeveloped issues.

Use a Two-Speed Assessment

Not every signal requires an enterprise-wide risk assessment. Compliance needs two speeds. The first is rapid triage. A small group of subject-matter experts identifies the potential legal obligation, affected operations, time horizon, severity, available data, current controls, and immediate containment needs. This is where AI can play a key role in compliance, essentially superforecasting risks to enable quick, efficient risk management strategies when volatility hits. Additionally, such an approach may lead to a decision to monitor, take interim action, or launch a deeper review.

The second is formal assessment. Complex or high-impact risks may require structured interviews, data analysis, control testing, external counsel, forensic support, or scenario planning. The deeper process should be proportionate to the exposure, not triggered simply because the issue is new. This two-speed model protects agility without sacrificing rigor. It also creates evidence that the company made a reasoned decision. A short written triage record can show what information was considered, who participated, why the company chose its response, and when the issue will be reviewed again.

Convert Assessment Into Real Controls

The most common failure is not the inability to identify risk. It is the failure to convert assessment into a viable risk management strategy and then to implement, monitor, and improve your business operations. A new questionnaire, certification, or policy may create documentation, but documentation alone does not mitigate the underlying exposure.

Consider third-party risk. A supplier questionnaire can identify missing information, but the control lies in what happens next: enhanced diligence, contractual protection, source verification, payment restrictions, audit rights, monitoring, remediation, or a decision not to proceed. The same principle applies to AI. An AI-use policy matters, but effective governance also requires an inventory of use cases, approval gates, data controls, human oversight, testing, monitoring, and accountability.

Each response should identify the control objective, owner, implementation date, evidence, and testing method. Compliance should also ask what existing control can be adapted before building a separate program. Strong governance, escalation, training, data access, and investigation processes are reusable infrastructure across risk domains.

Resource allocation is part of that conversion. If a changing risk profile calls for deeper third-party monitoring, faster export review, or additional AI oversight, the organization must decide what people, technology, and budget will support the response. Compliance cannot claim to be risk-based when yesterday’s priorities continue to dictate today’s resources. The allocation decision, including any accepted constraint, should be visible and documented.

Treat Change Management as a Control

A technically correct response can still fail if employees do not understand it or the business cannot implement it. New requirements frequently collide with established incentives, systems, customer commitments, and local practice. Change management should therefore be part of the control design. Explain why the risk changed. Identify which decisions and workflows are affected. Train the employees and gatekeepers who must act differently. Provide a practical escalation route. Test understanding. Gather feedback. Then revise the process when implementation exposes friction or unintended consequences. For a full discussion of change management as a compliance control, listen to the podcast Ronnie Feldman and I did with Caveni Wong on this episode of Creativity and Compliance.

This is where blog post 1’s communication discipline comes into play. Compliance cannot adapt to risk through broadcast messages alone. It needs a two-way channel that tells employees what changed and tells compliance whether the response works in practice.

Measure Adaptation, Not Activity

The number of risk meetings or completed assessments says little about effectiveness. Better measures test whether the organization moves from signal to decision and from decision to control. Useful indicators include the time required to triage a material development, percentage of actions with named owners and deadlines, overdue remediation, control implementation and testing results, repeat exceptions, unresolved ownership disputes, and lessons incorporated from investigations.

Compliance should also examine whether resources shifted when risk shifted. A program that identifies a higher risk but leaves staffing, monitoring, and controls unchanged has produced analysis without management. The result should be a closed loop: detect, assess, assign, mitigate, test, and learn. That loop turns risk assessment from an annual artifact into a management process.

That transition is where program credibility is tested. Join us tomorrow as we consider how organizations scope investigations, preserve independence, establish consistency, document decisions, and convert findings into remediation. A dynamic risk process helps the company see the signal. A credible investigation determines what happened and what the organization must do next.

Bonus Questions for Compliance Professionals

  1. Which internal and external signals can change the company’s risk profile between formal assessments?
  2. Who has specific ownership for emerging risks that cross legal, compliance, operations, procurement, finance, and technology?
  3. What criteria determine whether an issue is monitored, triaged, escalated, or formally assessed?
  4. Can the company show how a recent risk assessment changed a policy, control, resource allocation, or business decision?
  5. Do substantive mitigation and ongoing monitoring support questionnaires and certifications?
  6. How quickly can the organization move from a weak signal to a documented decision?
  7. What recent investigation finding should change the current risk assessment?
Categories
Blog

Connected Compliance: Part 1 – Communication as the Operating System of Compliance

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. Over this four-part blog post series, we will examine those connections, beginning with the discipline that makes every other element work: communication.

Compliance professionals often describe communication as one element of a program. That description is too narrow. Communication is the operating system through which employees learn expectations, seek advice, identify risk, report concerns, and judge whether management means what it says. If that system is slow, generic, inaccessible, or untrusted, even well-designed controls can fail in practice.

This matters because a compliance program does not become effective when a policy is published or training is completed. It becomes effective when an employee facing pressure knows what to do, understands where to go, and believes that asking for help will not create a career problem. Communication is therefore not simply messaging. It is a preventive control, a detection mechanism, and a source of management information.

Communication Is a Control, Not a Campaign

Many organizations still approach compliance communication as a calendar exercise. They send a Code of Conduct message, deliver annual training, publish a hotline reminder, and count distribution. Those activities may be necessary, but they do not establish whether the message reached the employee at the moment of risk.

An effective communication control has four characteristics.

  1. It is accessible, so employees can find guidance without having to navigate a maze.
  2. It is relevant, so examples reflect the decisions employees actually face.
  3. It is interactive so that employees can ask questions and test judgment.
  4. It is responsive, so the organization uses employee feedback to improve policies, training, and controls.

These distinctions are important. A campaign pushes information out. A control creates a reliable exchange of information. That exchange gives compliance an early view of confusion, pressure, process weakness, and emerging misconduct. It also gives employees a practical path to lawful and ethical decisions.

What the DOJ Is Really Asking

The Department of Justice has moved the compliance discussion away from paper design and toward operational effectiveness. The three fundamental questions in the 2024 Evaluation of Corporate Compliance Programs (ECCP) examine the program’s design, empowerment, and whether it works in practice.

For culture, the DOJ asks, “Does the company seek input from all levels of employees?” It then asks, “What steps has the company taken in response to its measurement of the compliance culture?” Those questions place two obligations on compliance. First, the company must listen across levels, functions, and locations. Second, it must demonstrate that listening changed something. Data without response is observation, not effectiveness.

The ECCP also directs prosecutors to examine policy accessibility, training effectiveness, the availability of guidance, and whether employees know when to seek advice. Taken together, these questions make communication evidence. A company should be able to show not only what it said but also who could access it, whether employees understood it, how they used it, and what management learned from it.

Build Channels Around Employee Behavior

Employees do not experience the company through a single channel. They communicate through managers, messaging platforms, internal websites, employee groups, town halls, mobile devices, and informal workplace networks. A compliance program that relies on one formal channel will miss important signals.

The practical response is a channel portfolio. Policies should be searchable and written in language employees can use. Guidance should be available through live compliance contacts and appropriate digital tools. Reporting options should include the hotline, web intake, direct contact with compliance or human resources, and management escalation. Communications should reach operational employees who may not sit at a computer, as well as global employees who may face language or cultural barriers.

Compliance also needs to listen where employees are already speaking. That may include internal collaboration channels, employee surveys, focus groups, office visits, and patterns in questions received by the compliance team. Any monitoring must be consistent with law, privacy expectations, company policy, and records-management requirements. The goal is not surveillance. The goal is to understand the employee experience before a cultural weakness becomes a control failure.

Face-to-face contact remains especially valuable. A visit to a business unit can reveal whether employees understand a policy, whether managers create pressure, and whether the local process matches the written procedure. It also changes how employees see compliance. A familiar adviser is easier to contact than a distant function that appears only during training or an investigation.

Replace Training Completion With Decision Readiness

Completion rates answer whether an employee opened a course. They do not answer whether the employee can recognize a conflict, challenge a questionable payment, escalate an export-control concern, or pause the use of an unapproved AI tool. As Hui Chen continually reminds us, it is about results, not inputs.

Training should therefore be built around decision readiness. Scenario-based sessions allow employees to work through realistic gray areas and explain why one course of action is safer than another. Shorter, targeted modules can address risk by role. Experienced employees may be able to demonstrate proficiency through testing, while supervisors may require additional training because they receive concerns and translate policy into daily conduct.

Relevance is a control feature. Employees are more likely to retain training that reflects their workplace, business model, and actual risk. A procurement team needs different scenarios from a sales team. A manager needs to understand retaliation and escalation. An engineer needs clear boundaries around data, cybersecurity, and AI. Localization must also address more than translation. Examples, delivery methods, and escalation paths should make sense in the local operating environment. The measurement should move beyond completion. Useful indicators include questions asked after training, repeat areas of confusion, scenario performance, requests for advice, policy-page use, control exceptions, and whether similar misconduct declines over time.

Make Leadership Visible and Consistent

Tone at the top loses force when it sounds scripted or appears only once a year. Employees judge leadership commitment through repeated choices: which risks receive attention, whether high performers are disciplined, whether managers welcome questions, and whether business pressure routinely overrides control requirements.

Compliance communication is stronger when leaders explain expectations in their own voices and connect them to business responsibilities. The chief executive can frame integrity as part of strategy. Finance can address books and records. Human resources can speak to respect, retaliation, and accountability. Business leaders can explain why escalation protects customers and sustainable growth.

Middle management is equally important. Most employees experience culture through their direct supervisor. Managers should be trained to receive concerns, avoid promises they cannot keep, protect confidentiality, escalate promptly, and prevent retaliation. If employees hear an ethical message from senior leadership but experience dismissal from a supervisor, the local message will win. Consistency completes the control. The organization must apply standards across rank, geography, and commercial importance. Unequal treatment communicates more powerfully than any policy statement.

Use Data Without Losing the Human Signal

Technology can help compliance measure reach and engagement. Policy-page analytics can show whether employees use key resources. Digital guidance tools can identify common questions. Investigation and reporting data can reveal trends by issue, region, or function. Training results can show where judgment remains weak.

These data points should be treated as signals, not verdicts. High question volume may indicate confusion, but it may also show that employees trust compliance. An increase in reports may reflect more misconduct, a successful awareness campaign, or greater confidence in the reporting process. Low reporting may indicate a healthy environment, or it may be a warning that employees believe speaking up is futile.

The best analysis combines quantitative and qualitative evidence. Compliance should compare usage data with employee interviews, survey responses, investigation themes, audit findings, exit information, and observations from business partners. It should protect privacy, limit access, and avoid metrics that encourage the wrong behavior. A target that simply seeks fewer reports can suppress the very information the company needs.

Convert Listening Into Action

The strongest evidence of culture is not the survey itself. It is what the company does next. If employees cannot find a policy, redesign access. If repeated questions reveal ambiguity, rewrite the guidance. If a region reports little despite known risk, test for fear or channel barriers. If investigations identify manager misconduct, adjust training, incentives, supervision, and discipline.

This requires a closed-loop process. Gather information. Analyze it for themes and root causes. Assign ownership for action. Document the decision. Communicate appropriate changes. Then measure whether the change worked. That process turns communication into continuous improvement and creates a defensible record of program evolution.

It also connects this first installment to the rest of the series. Employee questions and reporting patterns are early risk indicators. Investigation quality tells employees whether the company acts on what it hears. Whistleblower-program credibility determines whether critical information enters the system at all. Each element depends on the others.

From Culture to a Shifting Risk Environment

Communication gives compliance something more valuable than reach. It provides intelligence. Questions about a new market, an AI application, a third party, a customer demand, or a supply-chain disruption may be the first evidence that the risk environment has changed.

Join us tomorrow for our next installment, where we will examine how compliance can convert those signals into dynamic risk assessment, clear ownership, and adaptive controls. A shifting risk environment cannot be managed by an annual exercise alone. It requires the listening discipline established here.

Bonus Questions for Compliance Professionals

  1. Can employees find practical guidance at the moment they face a risky decision?
  2. Which groups, locations, or shifts are least engaged with compliance resources, and why?
  3. What evidence shows that employee feedback has changed the program?
  4. Are managers prepared to receive concerns, escalate them, protect confidentiality, and prevent retaliation?
  5. Do current metrics reward learning and trust, or do they unintentionally reward silence?
  6. What recent employee question should be treated as an emerging-risk signal?
Categories
Blog

Scoular’s $10 Million FCPA Resolution: Compliance Lessons Learned

We conclude our review of the Scoular Company FCPA enforcement action with a full lessons-learned blog post. We are still awaiting the DPA and Criminal Information, so the details of the case come from the Department of Justice (DOJ) Press Release.

A $2,000 payment can disappear inside a global supply chain. Repeated, train-by-train, authorized by employees, routed through customs brokers, discussed on WhatsApp, disguised as a “reinspection fee,” and reimbursed for six years, it becomes an operating model. That is the central lesson from The Scoular Company Foreign Corrupt Practices Act resolution.

The DOJ announced that Scoular Company would pay more than $10 million to resolve an investigation into bribes paid to Mexican officials between 2013 and 2019. The company entered into a three-year deferred prosecution agreement, agreed to a $9,769,521 criminal penalty and $414,351 in forfeiture, and accepted continuing cooperation, compliance, and reporting obligations.

Across this blog post series, we examined four dimensions of the case: customs brokers and payment controls, cartel and national-security risk, off-channel communications, and the facilitating-payments exception. Read together with my podcast conversation with Matt Ellis, they reveal a single conclusion. Compliance must follow the complete transaction, from the business pressure that creates the payment to the third party that delivers it, the message that authorizes it, the invoice that conceals it, and the ultimate recipient who benefits.

The Scheme Hid in Plain Sight

According to the DOJ, Scoular Company relied on customs brokers to move corn and other agricultural products from the United States into Mexico. Mexican authorities inspected the shipments for dirt, soil, and other impurities. When inspections identified problems, Scoular Company employees directed brokers to pay officials approximately $2,000 per train so the shipments could cross the border. The brokers invoiced the payments back to Scoular Company as “reinspection fees,” and Scoular paid them. In total, the company authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs.

The invoice description is the first major lesson. “Reinspection fee” sounded like it was connected to a legitimate customs process. Yet an accounts-payable control that merely matches an approved vendor, purchase order, and plausible service description tests paperwork, not substance.

Effective payment controls should require the company to identify the government agency involved, match the charge to a specific shipment and inspection, compare the amount with an official fee schedule, obtain proof of service, confirm the payee, and document the business justification. Repeated round-dollar charges, unusual success rates, rapid clearance after special payments, and fees unsupported by government records should trigger review.

Follow the money, measure the time, and test the outcome. That is how ordinary transaction data becomes an anti-corruption control.

A Licensed Broker Is Still a High-Risk Third Party

Customs brokers should never be treated as low-risk administrative providers simply because they are licensed or legally required. They interact with government officials, operate under commercial pressure, and can impose charges that distant finance personnel cannot easily verify.

Initial due diligence remains necessary, but it is only the beginning. Companies must connect screening, contracting, invoice testing, transaction monitoring, recertification, training, audit rights, and offboarding. The real test is not whether the third-party file was complete on the day of onboarding. It is whether the company understands how the broker behaves after the contract is signed.

The DOJ credited Scoular Company with eliminating brokers associated with the Mexican reinspection payments, strengthening risk-based screening and approvals, adding anti-corruption and audit-rights provisions, revising controls for high-risk transactions, and using software tools to improve monitoring. That remediation changed the operating model rather than merely revising a policy.

Cartel Risk Changes the Compliance Perimeter

The most consequential part of the DOJ announcement may be its national-security framing. The government determined that, without Scoular Company or its employees knowing it, a portion of the bribes benefited persons associated with a cartel’s criminal operations at the U.S.-Mexico border.

U.S. Attorney Justin R. Simmons stated that American companies engaged in cross-border trade bear responsibility for operating without benefiting cartels or threatening national security. Ellis challenged the literal breadth of the statement during our podcast discussion. Legitimate trade crosses the border every day without companies knowingly paying cartels. Nevertheless, he agreed that the statement signals a more demanding compliance environment.

Ellis explained that the cartel and transnational criminal organization risk is broader than the traditional FCPA risk. Anti-corruption diligence often concentrates on government touchpoints and intermediaries. Organized crime may be hidden inside transportation providers, suppliers, customers, labor relationships, security services, subcontractors, and local routes.

Traditional database screening may not reveal those connections. Ellis emphasized contextual diligence: speak with employees on the ground, examine local security concerns, understand regional criminal activity, investigate facts that do not add up, and adjust operations when warning signs emerge. Companies do not need perfect knowledge. They need a documented story of reasonable measures, credible escalation, and risk-based decisions.

The practical consequence is an integrated risk assessment. Anti-corruption, sanctions, anti-money laundering, trade compliance, physical security, supply chain, and third-party risk cannot remain in separate silos when the same payment may touch all of them.

WhatsApp Was Part of the Control Environment

The DOJ said Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. WhatsApp was therefore not a side issue. It allegedly carried the knowledge and direction behind transactions later recorded as legitimate reinspection charges.

An informal application becomes a business system when employees use it to direct third parties, approve payments, or resolve customs problems. Enterprise controls can be bypassed when the substantive decision occurs in a private chat, and the formal system records only the sanitized result.

Ellis noted that a complete WhatsApp ban may be unrealistic in Latin America. The better approach is to map actual use and define what may occur on each platform. Logistical coordination may be permitted. Government interactions, payment approvals, contractual commitments, and exceptions should remain in controlled systems with retention and audit trails.

Companies must also be able to preserve and retrieve business communications lawfully from company and personal devices. Policies should address device replacement, departing employees, legal holds, privacy and employment requirements, refusal of access, and consistent discipline. The decisive question is not whether a policy exists. It is whether the company can obtain the evidence when an investigation begins.

Why These Were Not Facilitation Payments

The $2,000 amount and the customs setting may tempt employees to use the phrase “facilitation payment.” That label does not fit. The FCPA’s narrow exception covers payments intended to expedite routine, nondiscretionary governmental action that the payer is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not.

The Scoular Company payments allegedly changed the result. The shipments had identified impurities, and the payments allowed trains to cross despite those findings. The company received a substantial business advantage by avoiding more than $6.5 million in costs. A facilitation payment is not defined by size, local custom, commercial urgency, or invoice terminology. A third party cannot create an exception unavailable to the principal. Nor does an anti-bribery exception excuse false accounting. Even a qualifying payment must be accurately recorded and supported by adequate internal controls.

Ellis’s discussion of extortion reinforces the operational lesson, although extortion and facilitation are distinct doctrines. One or two emergency payments may present a different analysis from a chain of payments continuing over years. Repetition transforms an asserted accommodation into a business process. Companies must respond by escalating, rerouting, changing providers, investigating, and remediating.

Cooperation Still Matters

Scoular Company did not receive voluntary self-disclosure credit because it did not report the conduct to the DOJ in a timely manner. It did receive cooperation credit for its internal investigation, factual presentations, identification of involved individuals, production and organization of evidence, and provision of counsel for current employees, despite early deficiencies.

The resulting criminal penalty reflected a 25 percent reduction from the bottom of the applicable sentencing guidelines range. The lesson is straightforward. Missing the voluntary disclosure window does not render later cooperation irrelevant, but cooperation is not a substitute for timely self-disclosure. The Scoular Company resolution is not four separate compliance stories. It is one story about how pressure, third parties, communications, accounting, and emerging national-security risks converged inside an ordinary business process.

The enduring lesson is equally integrated: know the broker, validate the payment, preserve the message, understand the route, and test the outcome. That is how compliance moves from policy to proof.

Categories
Blog

The $2,000 Question: Why Scoular’s Bribes Were Not Facilitation Payment

We continue our exploration of the Scoular FCPA enforcement action. We are still awaiting the DPA and Criminal Information, so the details of the case are based on the Department of Justice (DOJ) Press Release. Today we take up a topic little commented on anymore, but this enforcement action provides an opportunity to discuss, review, and explore facilitation payments.

The phrase “facilitation payment” is one of the most dangerous phrases in anti-corruption compliance. It sounds technical. It sounds modest. It can make an improper payment appear to be a recognized cost of moving goods through a difficult market. When a customs broker says that a small payment is necessary to get a train across the border, the business may hear urgency, local custom, and operational necessity.

The Foreign Corrupt Practices Act hears a different question: Was the official merely being paid to perform a routine act that the company was already entitled to receive, or was the payment intended to change the official’s decision and secure an improper business advantage? That distinction resolves the issue in The Scoular Company enforcement action.

According to the Department of Justice, Mexican inspections found dirt, soil, and other impurities in Scoular shipments. Scoular employees then directed customs brokers to pay Mexican officials approximately $2,000 per train so the shipments would cross the border despite those findings. The brokers invoiced the payments back to Scoular as “reinspection fees.” The alleged payments did not accelerate a routine action. They changed the result of an inspection. That is why the facilitation payments exception does not apply.

The Exception Is Narrow by Design

The original 1977 FCPA excluded payments for duties that were essentially ministerial or clerical. Congress revised the statute in 1988 and defined the modern exception for facilitating or expediting payments made to secure the performance of “routine governmental action.”

The statute gives examples:

  • Obtaining permits, licenses, or other official documents needed to do business
  • Processing government papers such as visas and work orders
  • Providing police protection or mail service
  • Scheduling inspections connected with contract performance or the transit of goods
  • Providing telephone, power, or water service
  • Loading and unloading cargo
  • Protecting perishable products from deterioration

The list can mislead a hurried business employee. Inspections and cargo appear in the statute. Scoular involved inspections and cargo. That superficial similarity is not enough. Congress expressly excluded decisions about awarding new business or continuing business with a particular party. The core principle is that routine governmental action does not include discretionary decisions that are the functional equivalent of obtaining or retaining business or securing an improper advantage. The exception is about speeding up the official’s performance of an existing duty. It is not about purchasing a favorable decision.

What a Facilitation Payment Is

A true facilitation payment has four characteristics.

  1. Routine. The governmental act is routine. The official performs it in the ordinary and customary manner. The act does not require a substantive judgment about whether the company has met a legal or regulatory standard.
  2. Entitled. The payer is already entitled to the action. The official has no lawful basis to deny the service. The payment changes timing, not entitlement.
  3. No Discretion. The official exercises no meaningful discretion. The official may control the pace of processing, but not the substantive outcome.
  4. Intent. The purpose is to expedite performance. It is not to influence an official to ignore a violation, reverse an adverse decision, waive a requirement, or confer a competitive advantage.

Consider the difference between scheduling an inspection and passing one. A small payment to move an inspection request from an ignored pile into the ordinary scheduling process may fall within the statutory language, subject to all the other legal and policy risks. A payment to persuade the inspector to overlook contamination does not. The first payment seeks action. The second purchases an outcome.

What a Facilitation Payment Is Not

A facilitation payment is not defined by amount. The FCPA contains no safe harbor for $20, $200, or $2,000. A small bribe remains a bribe when its purpose is to influence discretion. It is not defined by local custom. “Everyone pays it” is evidence of a risk of corruption, not a legal defense. It is not defined by urgency. Perishable goods, demurrage, customer demands, and production interruptions can create enormous pressure. Commercial pressure does not convert a discretionary government decision into a ministerial act.

The name on the invoice does not define it. “Reinspection fee,” “expediting charge,” “special handling,” and “administrative support” are descriptions. Compliance must determine what the money was actually used for. It is not created because a third party made the payment. The FCPA reaches indirect payments and authorizations through agents. A customs broker cannot manufacture an exception that the principal could not claim directly. Finally, it is not a blanket authorization for customs payments. Customs functions combine routine processing with significant official discretion. Scheduling an inspection may be routine. Deciding that contaminated goods can enter the country is not.

Apply the test to Scoular

The DOJ’s allegations make the application straightforward.

The shipments had failed a substantive condition

Mexican law subjected the agricultural shipments to inspection for dirt, soil, and other impurities. According to the DOJ, inspections found those conditions. The company was therefore not waiting for an official to perform a duty it had already satisfied. It faced an adverse regulatory result.

The payments changed the outcome

The brokers allegedly paid officials to ensure that the trains crossed despite the inspection findings. That is the exercise of official discretion. The payments were not made merely to schedule or complete a reinspection. They allegedly caused officials to permit entry notwithstanding the problem.

The company obtained a substantial business benefit

The DOJ said Scoular authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs. The benefit was not faster paperwork alone. It was the avoidance of consequences associated with shipments that did not satisfy inspection requirements. That economic reality matters. A payment that yields more than $16 in avoided costs per dollar spent looks less like clerical acceleration and more like a mechanism for obtaining an improper advantage.

The conduct was repeated and organized

The scheme allegedly continued from 2013 through 2019 and involved multiple customs brokers. Scoular employees directed the payments, discussed them via WhatsApp and other channels, and paid the brokers’ reimbursement invoices.

In my podcast with Matt Ellis of Miller & Chevalier, Ellis addressed repeated payments in the related context of extortion. He explained that one or two emergency payments may present a different analysis, but a chain of payments over time makes reliance on a defense far more difficult. Extortion and facilitation payments are distinct legal doctrines. Still, Ellis’s practical point applies with full force here. Repetition changes the compliance story. A recurring payment is not an emergency response. It becomes part of the operating model.

The invoices did not call the payments what they were

The brokers allegedly invoiced the bribes as reinspection fees. Even a payment that qualifies for the narrow anti-bribery exception must be accurately reflected in an issuer’s books and records. The exception is not permission to conceal the true nature of an expenditure. This creates a central compliance paradox. Employees may resist recording a “facilitation payment to customs official” because the description raises legal, ethical, and local-law concerns. They may then use a vague or misleading account description, creating separate books and records and internal control risks. The invoice label in Scoular did not solve the problem. It became evidence of it.

Do Not Confuse Facilitation With Extortion

Companies must also distinguish the facilitation-payments exception from an extortion or duress analysis. A facilitation payment concerns the nature of the governmental action. Was it routine and nondiscretionary? Extortion concerns coercion. Was an individual facing a genuine threat to life, health, safety, or liberty? Ordinary economic pressure, such as delay costs or lost business, generally does not carry the same significance as a threat of physical harm.

Ellis stressed that companies confronting cartel and extortion risks should examine whether an event is isolated, whether alternative routes or providers exist, what remediation was undertaken, and whether management changed the conditions that allowed the payments to continue. His broader advice was that a company must be able to tell a credible story of reasonable measures and operational adjustment. Scoular’s alleged six-year payment pattern is difficult to reconcile with that story. The operational response was not to stop, reroute, escalate, or remediate. It was allegedly to reimburse the brokers and continue moving trains.

The Accounting Provisions Remain

Another recurring error is to assume that an anti-bribery exception eliminates all FCPA risk. It does not. The FCPA’s accounting provisions require issuers to keep books and records that accurately and fairly reflect transactions and to maintain adequate internal accounting controls. A payment may fall outside the anti-bribery prohibition and still create liability if it is mischaracterized, hidden in a miscellaneous account, or made through controls that do not provide reasonable assurance of proper authorization and recording. The DOJ FCPA Resource Guide 2nd edition explains these requirements and the government’s narrow approach to the exception.

That is why a company policy that allows facilitation payments creates operational difficulties. Employees must make fine legal distinctions under pressure, document a payment that may violate local law, obtain appropriate approval, and record the transaction transparently. Many companies reasonably prohibit facilitation payments altogether. The legal exception is so narrow, and the collateral risks so substantial, that a global ban is often easier to explain, control, and test.

A Better Customs Control

When a broker describes a payment as a facilitation payment, compliance should treat the statement as the starting point for the inquiry.

The company should ask:

  1. What exact government action is requested?
  2. Is the company already legally entitled to that action?
  3. Does the official have discretion over the outcome?
  4. Has an inspection, permit, or application already produced an adverse result?
  5. Will the payment change only timing, or will it change the result?
  6. Is the amount supported by a published fee schedule and an official receipt?
  7. Who will receive the money?
  8. Is the payment lawful under local law and permitted by company policy?
  9. How will it be recorded in the books?
  10. Has the same broker, port, product, or payment description appeared before?

If the business cannot answer those questions before payment, it should not rely on the exception.

Questions for CCOs and the Final Lesson

CCOs should ask whether employees understand the difference between scheduling an inspection and buying a successful inspection. They should test customs invoices for recurring round-dollar charges, match fees to official documents, and review whether brokers produce unusually favorable outcomes after special payments.

The Scoular lesson is simple. A payment does not become permissible because it is small, customary, urgent, or routed through a broker. It qualifies for the FCPA’s narrow exception only when it expedites a routine, nondiscretionary action that the company is already entitled to receive. Scoular’s alleged payments did something very different. They caused officials to allow shipments across the border despite failed inspections, avoided millions of dollars in costs, and were disguised as reinspection fees.

That was not facilitation. It was the business purpose of the bribery scheme.

Categories
Blog

What Scoular Teaches About Off-Channel Communications, Investigations, and Compliance Program Effectiveness

WhatsApp was not a footnote in The Scoular Company FCPA resolution. It was part of the operating system of the alleged bribery scheme. According to the Department of Justice Press Release (we are still waiting on the DPA and Criminal Information), Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. Today I want to explore the issue of off-channel communication and what it means for your compliance program.

The compliance lesson is not simply that Scoular Company employees used WhatsApp. It is that an informal communications channel became embedded in a high-risk business process involving customs officials, third-party brokers, payment approvals, and financial records. Once that happens, messaging governance is no longer an information technology issue. It is an anti-corruption control.

Off-Channel Became the Business Channel

The phrase “off-channel” can be misleading. If employees regularly use WhatsApp to authorize payments, direct third parties, and solve customs problems, the application is not outside the business. It is where the business is being conducted. That distinction matters.

A company may have excellent controls inside its enterprise resource planning system. It may require purchase orders, segregation of duties, invoice matching, and documented approvals. Those controls can be bypassed if the substantive decision is made in a private chat and the formal system merely records the result. At Scoular Company, the reinspection invoice was one side of the control failure. The WhatsApp discussion was the other one.

The invoice gave the payment a facially legitimate description. The messaging channel allegedly supplied the knowledge, direction, and authorization behind it. Compliance teams should test both sides together. A recurring round-dollar customs charge becomes more significant when matched to a message asking a broker to get a train released. A failed inspection becomes more significant when followed by an off-channel approval and immediate border clearance. Communications analytics and transaction analytics should not operate as separate disciplines.

Enforcement Priorities Can Change. Evidence Does Not.

In my podcast with Matteson Ellis, Member and Latin America Practice Lead at Miller & Chevalier, we addressed the shift in federal enforcement attention surrounding off-channel communications. Ellis made the more durable point: even when a regulator changes its emphasis, WhatsApp messages remain evidence of knowledge, intent, authorization, concealment, and circumvention of control.

Ellis observed that the DOJ press release suggests Scoular’s internal investigation obtained access to relevant WhatsApp communications. That access was important because retrieving such data can be difficult, particularly when employees use personal devices, local privacy law limits review, or messages have not been retained. His conclusion should command the attention of every CCO. The off-channel issue may have become quieter, but the Scoular resolution can be read as bringing it back to the center of corporate investigations. A prosecutor does not need a standalone recordkeeping case to use a WhatsApp message as proof of an FCPA violation.

The 2024 ECCP Provides the Road Map

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP) does not demand a single technology solution. It asks whether the company’s approach is reasonable for its business needs and risk profile. That is the correct standard because messaging use varies by country, function, and commercial reality. The ECCP organizes the inquiry around three practical areas:

  • Communication channels. What electronic channels do employees actually use? How does use vary by jurisdiction and business function? What retention and deletion settings apply, and why did the company permit them?
  • Policy environment. Can the company preserve communications when devices are replaced? What do privacy, security, employment, and bring-your-own-device rules permit? Can the company review business messages on personal devices, and are employees required to transfer business records into company systems?
  • Risk management. Has the company ever exercised its access rights? What happens when an employee refuses access or violates the policy? Has messaging use impaired an investigation or the company’s response to prosecutors?

These are effectiveness questions. A written prohibition will not satisfy them if the business routinely ignores it, managers approve transactions in private chats, and the company cannot retrieve the records when misconduct surfaces.

A Defensible Program Starts With Commercial Reality

Ellis explained that an outright WhatsApp ban may not be practical in Latin America, where the application is widely used for business. A policy that conflicts with how employees, customers, and third parties actually work may drive communications further underground. The better approach is to define what may occur on the platform.

Ellis suggested limiting WhatsApp to logistical and administrative communications while keeping substantive commercial transactions and approvals inside controlled systems. That distinction is particularly important for customs payments, discounts, government interactions, third-party instructions, and exceptions to standard procedures.

A defensible framework should include the following controls:

  • Map actual use: Survey high-risk functions and jurisdictions to determine which applications, devices, disappearing-message settings, and informal groups employees use.
  • Classify communications: Separate low-risk logistics from approvals, commitments, payment decisions, government interactions, and other substantive business records.
  • Build technical access: Use company-managed devices or approved enterprise integrations where appropriate so business communications can be retained, searched, placed on legal hold, and produced.
  • Address local law: Analyze privacy, employment, consent, monitoring, and data-transfer requirements before an investigation begins. The access right must be lawful and operational.
  • Create preservation protocols: Define what occurs when an employee changes devices, leaves the company, becomes subject to a legal hold, or refuses access to business communications.
  • Enforce the rules: Test compliance, investigate violations, apply consequences consistently, and examine whether supervisors tolerated or encouraged off-channel approvals.

Investigations Must Be Ready Before the Message Disappears

Off-channel governance is tested in the first hours of an investigation. The company must identify relevant custodians, devices, applications, group chats, backup settings, linked desktops, and cloud accounts. It must issue a preservation notice that employees understand and implement. It must also determine whether consent, works council consultation, or another local-law step is required before collecting data.

The investigative team should not examine messaging data in isolation. It should connect communications to:

  • Accounts-payable records
  • Customs broker invoices
  • Inspection results
  • Shipment identifiers
  • Clearance times
  • Approval logs
  • Bank data

This is where Scoular Company FCPA enforcement action becomes a model for a broader control lesson. The message can explain the invoice, and the invoice can corroborate the message. Ellis emphasized the value of having protocols ready before access is needed. That is critical. Negotiating employee consent, locating backups, and determining ownership of a device after a subpoena or whistleblower allegation arrives is not a defensible strategy. It is a delay, and delay can destroy evidence and cooperation.

Boards Should Treat Messaging as a Governance Risk

Boards do not need to select the retention platform or approve device settings. They do need assurance that management understands how high-risk business is actually conducted and can preserve the evidence required to investigate misconduct. The board should receive more than confirmation that a policy exists. It should receive information on:

  • Policy exceptions
  • Control testing
  • Employee violations
  • Disciplinary outcomes
  • Collection failures
  • Investigation delays
  • High-risk jurisdictions and functions

For companies operating across the U.S.-Mexico border, customs, logistics, sales, procurement, and government-facing teams deserve particular attention. This is an oversight issue. If management cannot retrieve communications involving payments to government-facing third parties, the company may be unable to determine what occurred, identify responsible individuals, remediate the control failure, or cooperate effectively with prosecutors.

Questions for CCOs

  1. Which messaging platforms do employees and third parties actually use in our highest-risk markets?
  2. Can an employee approve a customs payment, direct a broker, or authorize an exception through WhatsApp?
  3. Can we lawfully and promptly preserve and retrieve business messages from company and personal devices?
  4. Have we tested those capabilities through a mock investigation or legal hold?
  5. Do transaction-monitoring reviews incorporate relevant messaging evidence when an anomaly is escalated?
  6. Have we disciplined employees and supervisors for circumventing approved channels?

The Bottom Line

Scoular Company did not become an off-channel communications case because employees happened to use WhatsApp. WhatsApp mattered because employees allegedly used it to facilitate and discuss a bribery scheme that operated through customs brokers and disguised invoices for six years. That is the compliance lesson. The channel, the payment, the third party, and the business outcome must be viewed as one control environment.

Companies should not ask whether WhatsApp is good or bad. They should ask whether the communications occurring there are permitted, preserved, accessible, monitored on a risk basis, and connected to the company’s formal approval and financial systems. If the company cannot answer those questions, its most important business records may be sitting on the device it controls least.

Categories
FCPA Compliance Report

FCPA Compliance Report: The Scoular FCPA Enforcement Action: Customs Bribes, Cartel Links, and New Compliance Expectations

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom welcomes back Matt Ellis to discuss a newly announced FCPA enforcement action involving Scoular Company.

The case invoiced about $400,000 in payments labeled as “reinspection fees” to Mexican customs and food inspectors to move agricultural goods across the Mexico–U.S. border. border, allegedly generating over $6.5 million in avoided costs and raising concerns about cartel-linked beneficiaries. They discuss why customs and customs brokers are recurring high-risk areas in Mexico, how long-running employee involvement suggests broader controls and tone-from-the-top failures, and why these payments are not facilitation payments under Mexican law and given discretionary official acts. Ellis emphasizes analytics on customs documents and broker invoices, stronger third-party diligence beyond traditional screening to address cartel/TCO risks, and defensible governance for WhatsApp/off-channel communications. Despite no voluntary self-disclosure, the company received cooperation credit and a 25% fine reduction, and Ellis previews an ACI conference focused on cartels, TCOs, and compliance in Latin America.

Key highlights:

  • Border Bribes and Safety Risks
  • Controls Failures and Monitoring
  • Data Analytics Red Flags
  • Facilitation Payment Myth
  • DOJ Cartel Warning and Implications
  • Rethinking Due Diligence for Cartels
  • WhatsApp and Messaging Governance
  • Cooperation, Credit, and Remediation

Resources:

Cartels, TCOs and Compliance in Latin America, July 20-21

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

The FCPA Compliance Report was recently named the world’s best business ethics podcast by FeedSpot.

Categories
Blog

Scoular’s $10 Million FCPA Resolution: When a “Re-inspection Fee” Becomes a Bribe

A $2,000 payment can look insignificant inside a global supply chain. Repeated train by train, approved by employees, routed through customs brokers, disguised on invoices, and paid for six years, it becomes something else entirely. For The Scoular Company, it became a Foreign Corrupt Practices Act enforcement action carrying more than $10 million in penalties and forfeiture, a three-year deferred prosecution agreement, continuing cooperation obligations, and periodic reporting to the Department of Justice.

The case is an important warning for every company engaged in cross-border trade. Customs brokers are not merely logistics providers. Border payments are not merely operational expenses. A mislabeled invoice is not merely an accounting problem. Each may represent an interconnected risk across anti-corruption, internal control, third-party, and national security.

The Scheme: $2,000 per Train

According to the DOJ Press Release (the full DPA is not yet available), between 2013 and 2019, Scoular used customs brokers to move shipments of corn and other agricultural products from the United States to Mexico. Mexican authorities inspected those shipments for dirt, soil, and other impurities. When inspectors identified problems, Scoular’s customs brokers allegedly paid Mexican officials approximately $2,000 per train to ensure that the shipments crossed the border.

The brokers then invoiced those payments back to Scoular as “reinspection fees.” Scoular paid the invoices. This was not an isolated facilitation payment or a rogue third party operating beyond the company’s knowledge. According to the court documents, Scoular employees authorized the payments, directed the brokers, and communicated about the shipments and bribes through WhatsApp and other channels.

The numbers demonstrate the business impact:

  • More than $400,000 in bribes authorized
  • More than $6.5 million in avoided fees and costs
  • A $9,769,521 criminal penalty
  • $414,351 in forfeiture
  • A three-year DPA

The company was charged with conspiracy to violate the FCPA’s anti-bribery provisions.

The Invoice Description Was a Compliance Red Flag

The phrase “reinspection fee” should be at the center of every compliance discussion about this case. The brokers did not invoice Scoular for bribes. They used a description that appeared facially connected to a legitimate customs process. That description allowed the payments to move through the company’s financial system.

This is how corruption frequently enters the books and records. It appears as:

  • Expediting fees
  • Administrative charges
  • Local processing costs
  • Customs support
  • Special handling
  • Reinspection fees
  • Consulting services

The compliance question is not whether the description sounds legitimate. The question is whether the company can establish what service was performed, who performed it, why the payment was necessary, how the amount was calculated, and who ultimately received the money. Accounts payable controls that merely match an invoice to a purchase order will not detect this type of scheme. Effective controls must examine the commercial substance of high-risk payments.

For customs-related expenses, companies should require supporting government documentation, published fee schedules, proof of service, payment to an authorized government account where appropriate, and enhanced approval for unusual or recurring charges.

Third-Party Due Diligence Is Only the Beginning

The Scoular resolution also demonstrates the limits of onboarding due diligence. A company can screen a customs broker, obtain certifications, execute an anti-corruption clause, and still face substantial FCPA exposure. The real question is what happens after the third party begins work. The answer is that the real work of compliance begins when the third-party contract is signed.

Customs brokers operate at the intersection of government interaction, time-sensitive business demands, discretionary enforcement, and local pressure. That makes them inherently high risk. An effective third-party management program should connect the following:

  • Initial due diligence
  • Contractual controls
  • Transaction monitoring
  • Invoice testing
  • Business justification
  • Periodic recertification
  • Audit rights
  • Compliance training
  • Offboarding decisions

The DOJ credited Scoular for strengthening risk-based screening and approval requirements, adding anti-corruption and audit-right provisions to contracts, and improving monitoring procedures. The company also eliminated customs brokers associated with the Mexican reinspection payments. Due diligence is not and cannot remain a static file. It must become a continuing control system tied to actual payments and operational conduct.

WhatsApp Was Part of the Business Process

Scoular employees allegedly communicated about the shipments and payments through WhatsApp and other channels. This fact should concern every CCO. When employees use personal devices or ephemeral messaging platforms to conduct high-risk business, the company may lose visibility into precisely the communications it most needs to monitor, preserve, and produce.

The answer is not necessarily to prohibit every messaging application. The answer is to establish a defensible governance model addressing the following:

  • Permitted communication platforms
  • Business-record retention
  • Preservation during investigations
  • Access to relevant communications
  • Training for high-risk employees
  • Monitoring based on legal and privacy requirements
  • Consequences for circumventing approved systems

A policy without technical controls, employee training, and consistent enforcement is unlikely to satisfy prosecutors. Messaging governance must reflect how employees actually conduct business.

Corruption Is Now a National Security Issue

The most significant feature of the case may be the DOJ’s treatment of cartel risk. The government determined that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border. The DOJ stated that neither Scoular nor its employees knew about that connection. That lack of knowledge did not eliminate the seriousness of the issue.

Indeed, in the DOJ Press Release, U.S. Attorney Justin R. Simmons for the Western District of Texas was quoted as follows, “Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels.” Further, any American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security.”

The enforcement message is clear: companies operating in high-risk border regions must consider where third-party payments may ultimately flow. A payment intended to resolve a customs problem can expose a party to corruption, money laundering, sanctions, organized crime, and national security risks. This means anti-corruption risk assessments can no longer operate in isolation. Compliance teams should integrate information from the following:

  • Anti-money laundering reviews
  • Sanctions screening
  • Security functions
  • Trade compliance
  • Supply chain risk management
  • Third-party intelligence
  • Government investigations
  • Adverse media monitoring

The government is examining the complete risk created by a payment, not merely the employee’s immediate objective.

No Voluntary Disclosure Credit, but Meaningful Cooperation Credit

Scoular did not receive voluntary self-disclosure credit because it did not promptly report the conduct to the DOJ Fraud Section. It did, however, receive credit for cooperation. The DOJ cited Scoular’s internal investigation, factual presentations, identification of individuals involved, document production, organization of evidence, and provision of counsel for current employees. The DOJ also acknowledged deficiencies during the early stages of the investigation.

After considering the company’s cooperation and remediation, the DOJ imposed a criminal penalty reflecting a 25 percent reduction from the bottom of the applicable sentencing guidelines range. This is a valuable lesson in enforcement mathematics. Missing the opportunity for voluntary disclosure does not make subsequent cooperation irrelevant. Companies can still improve outcomes through credible investigation, evidence preservation, individual accountability, timely remediation, and the organized production of information.

Yet cooperation credit is not the equivalent of voluntary disclosure credit. The decision window following discovery of potential misconduct remains critical.

Remediation Must Change the Operating Model

Scoular’s remediation went beyond issuing a new policy. According to the DOJ, the company:

  • Conducted an external compliance maturity assessment and anti-corruption risk assessment
  • Restructured its compliance function
  • Increased senior leadership oversight
  • Eliminated brokers connected to the payments
  • Strengthened risk-based monitoring through software tools
  • Revised its Code of Conduct and key compliance policies
  • Improved third-party screening and approvals
  • Added anti-corruption and audit-rights provisions
  • Revised financial controls for high-risk transactions
  • Delivered general and targeted anti-corruption training

This is the type of remediation contemplated by the DOJ’s Evaluation of Corporate Compliance Programs. It addresses root causes, resources, governance, controls, technology, training, and business ownership.

The key is operational impact. The company must be able to demonstrate that the same conduct could not pass through the organization today without being detected or escalated.

Questions for CCOs

CCOs should ask:

  • Do recurring payments cluster around specific ports, brokers, officials, products, or inspection events?
  • Are vague payment descriptions automatically escalated?
  • Does compliance have access to customs, logistics, and accounts payable data?
  • Are high-risk brokers periodically reviewed after onboarding?
  • Has the company tested whether audit rights can actually be exercised?
  • Is there a rapid escalation process for deciding whether potential misconduct should be voluntarily disclosed?

The Bottom Line

The Scoular case was not simply about customs brokers paying officials. It was about an operational process that allegedly normalized bribery, an invoicing system that disguised the payments, employees who communicated through informal channels, and third-party funds that ultimately touched cartel-linked actors.

For compliance professionals, the lesson is direct: follow the payment, test the business justification, examine the communication channel, and understand the complete risk ecosystem. A $2,000 “reinspection fee” may be small enough to escape executive attention. It is not small enough to escape the FCPA.

Categories
Blog

The Odyssey and Compliance, Part 5 – Peace in Ithaca: Building the Program After the Crisis

Today, we conclude our five-part series on some of the intersections of. On Monday, we began with the Trojan Horse as a control failure. On Tuesday, we looked at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we reviewed The Cattle of Helios, Non-Negotiables, and Control Breaches. Today, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Odysseus finally makes it home. After ten years of war and ten more years of wandering, he returns to Ithaca, confronts the suitors, reclaims his house, and restores his position. The bow is strung. The suitors are defeated. The great crisis is over. Roll credits, cue heroic music, and let everyone go back to normal. Except, of course, that is not how governance works.

The story does not really end when Odysseus wins. Ithaca still has to be governed. The household has to be restored. Trust has to be rebuilt. Loyalties have to be sorted out. The damage done by years of disorder has to be addressed. Penelope, Telemachus, the servants, the suitors’ families, and the broader community all have to live with what comes next.

That is the overlooked compliance lesson at the end of The Odyssey: winning the confrontation is not the same as rebuilding the system. For corporate compliance, Ithaca is the company after an enforcement action, a scandal, a cyber breach, a restatement, a leadership crisis, a whistleblower investigation, a failed audit, or a major control breakdown. The dramatic event may be over. The press release may be issued. The investigation may be closed. The bad actors may be gone. But the real question remains: what changes must be made so that the same story does not happen again?

The Corporate Translation

Every organization wants to believe that removing the wrongdoer solves the problem. Terminate the employee. Discipline the manager. Replace the vendor. Restate the numbers. Settle the matter. Announce new leadership. Launch a refreshed values campaign. Hold a town hall. Add a slide to the annual training deck. All of those may be necessary.

None of them is sufficient. A crisis reveals more than individual misconduct. It reveals how the organization enabled the misconduct, overlooked it, tolerated it, rationalized it, or failed to respond sooner. It exposes weaknesses in governance, incentives, supervision, reporting, monitoring, controls, culture, and accountability.

That is why post-crisis remediation cannot be treated as corporate housekeeping. It is not the ceremonial sweeping of the hall after the suitors have been removed. It is the hard work of rebuilding Ithaca so the suitors do not return wearing different badges. The corporate lesson is simple: winning the investigation is not the same as rebuilding trust.

“Works in Practice” Is the Hard Question

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks three core questions: whether the program is well designed, whether it is adequately resourced and empowered to function effectively, and whether it works in practice. The ECCP makes clear that prosecutors consider how a company’s program performed at the time of misconduct and at the time of a charging decision or resolution.

That third question—does it work in practice? —is the Ithaca question. It is one thing to have a Code of Conduct. It is another thing to know whether employees believe it. It is one thing to have a hotline. It is another thing to know whether people trust it. It is one thing to discipline misconduct. It is another matter to know whether discipline is consistent across ranks, geographies, and revenue contributions.

A compliance program does not work because it is beautifully documented. A compliance program works when it changes decisions, identifies risks, encourages escalation, supports ethical behavior, and improves when reality proves that the initial design was not enough. Odysseus could reclaim the palace in a day. Rebuilding confidence in the palace would take longer. So it is with compliance.

Remediation Is Not a Memo

One of the great corporate temptations after a crisis is to confuse activity with remediation. There will be committees. There will be project plans. There will be executive updates. There will be dashboards in shades of green, yellow, and red. There will be a new policy with a title long enough to require its own table of contents. But the question is not whether the company became busier. The question is whether the company has become better.

Effective remediation begins with root cause analysis. What happened? Why did it happen? Who was involved? Who should have known? Which controls failed? Which controls did not exist? Were employees trained? Were managers supervising? Were incentives distorting behavior? Were prior warnings ignored? Were similar issues found elsewhere?

Then, remediation must move from diagnosis to design. Policies may need to change. Controls may need to be strengthened. Reporting channels may need to be rebuilt. Training may need to be targeted. Third-party relationships may need review. Compensation systems may need adjustment. Governance committees may need clearer authority. Data analytics may need to identify patterns earlier.

And then comes the part companies sometimes skip: testing and ongoing monitoring. A control is not considered remediated just because someone wrote that it was. A control is remediated when it has been implemented, tested, validated, and shown to work. Otherwise, Ithaca has merely repainted the door.

Monitoring and Testing: Trust, but Verify Ithaca

After a crisis, leadership often wants to move on. That impulse is understandable. No one wants to live forever in the investigation report. Employees are tired. Managers are defensive. The board wants assurance. Customers want stability. Regulators want evidence. The business wants to get back to business. But moving on too quickly is how organizations repeat themselves.

Monitoring and testing are the tools that keep memory alive without keeping the organization trapped in the past. Monitoring asks, “What are we seeing now? Testing asks, “Do the controls actually work?” Together, they turn compliance from a promise into evidence.

This is where ISO 37301 offers a useful management-system lens. ISO describes ISO 37301 as a compliance management systems standard for establishing, developing, implementing, evaluating, maintaining, and improving an effective and responsive compliance management system. That language matters because it treats compliance as a cycle, not a shrine. Establish. Implement. Evaluate. Maintain. Improve.

Culture Reset Requires More Than New Words

After misconduct, companies often rediscover culture with the enthusiasm of a traveler who has just realized the map was upside down. Suddenly, everyone wants to talk about values. Tone at the top. Speak-up culture. Accountability. Transparency. Trust.

But a culture reset requires more than new words from senior leadership. Employees are sophisticated consumers of corporate messaging. They know when a town hall is sincere and when it is theater. They know whether leaders who caused the pressure are still being rewarded. They know whether people who raised concerns were protected or isolated. They know whether the company wants the truth or merely closure.

A real culture reset asks hard questions. Are managers rewarded for ethical leadership? Are employees comfortable escalating concerns? Are investigations fair and timely? Are lessons learned communicated without unnecessary secrecy? Are senior leaders held accountable? Are compliance and audit findings taken seriously? Are business goals achievable without cutting corners? Culture is not reset by announcing that trust has been restored. Trust is restored when employees see different behavior over time.

Governance After the Storm

Ithaca’s problem was not only that the suitors behaved badly. It was the governance structure that allowed them to occupy the house for too long. That is a corporate issue as well.

After a crisis, boards and executive teams should examine whether governance failed. Did the right committees receive the right information? Did compliance have sufficient independence? Were risk owners clearly identified? Did internal audit, legal, HR, finance, security, and compliance coordinate effectively? Were red flags escalated? Did leadership understand the risk, or were they receiving sanitized reporting?

Governance redesign is not glamorous. It lacks the narrative thrill of Odysseus stringing the bow. But it is what prevents the next group of suitors from discovering that no one is really watching the door.

The Compliance Takeaway

The end of The Odyssey is not just about return. It is about restoration. That distinction matters for compliance officers and business leaders. After a crisis, the organization must resist the urge to declare victory too soon. The investigation may identify what happened. Discipline may address who was responsible. But remediation must answer the deeper question: what will be different? A mature compliance program uses a crisis as evidence. It monitors. It tests. It learns. It redesigns governance. It strengthens controls. It resets culture through action. It measures whether the program works in practice, not merely whether it exists on paper.

Odysseus came home and won back Ithaca. The compliance challenge is harder. You have to make Ithaca governable again.